--Lg8eXa+brxrbjAbR
Content-Type: text/plain; charset=us-ascii
Content-Disposition: inline
Content-Transfer-Encoding: quoted-printable
So if I have a RubyForge account I can upload a modified gem, of, say,
Rails, with a backdoor, and unknowing ruby users will accidentally install
it and open a backdoor in production rails servers?
=20
This sounds bad. VERY bad.
It is very bad. This is the exact problem the package signing in
RubyGems was written to address.
If only people were using it...
--=20
Paul Duncan <
[email protected]> pabs in #ruby-lang (OPN IRC)
http://www.pablotron.org/ OpenPGP Key ID: 0x82C29562
--Lg8eXa+brxrbjAbR
Content-Type: application/pgp-signature; name="signature.asc"
Content-Description: Digital signature
Content-Disposition: inline
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.0 (GNU/Linux)
iD8DBQFFrtXkzdlT34LClWIRAs0CAKDV+D+XN1eodKS5sh0+GJa7+nCgLgCgxcnR
rHRIMPkKMcYQN0nMKodhvog=
=d8HV
-----END PGP SIGNATURE-----
--Lg8eXa+brxrbjAbR--